Force Push
A force-push hid a commit, but ORIG_HEAD and the dangling object survived. Recovered the leaked reliquary credentials.
A force-push hid a commit, but ORIG_HEAD and the dangling object survived. Recovered the leaked reliquary credentials.
Analyzing NTUSER.DAT hives with RegRipper to trace CROWQUILL's stolen-credential access to vmarr's machine, uncovering KeeFarce credential theft and a staged/exfiltrated archive via 7-Zip artifacts.
Stored XSS via unescaped EJS output, CSP bypassed using a Google JSONP endpoint, payload delivered to an admin bot that exfiltrated the flag from the admin inbox back to us.
An Elysia backend's signed session cookie fails to verify signatures (CVE-2025-66457), letting a forged session=inside cookie bypass auth.
Fingerprinted a Telnet service running vulnerable GNU InetUtils telnetd, exploited CVE-2026-24061 via USER env injection to bypass auth and grab root shell + flag.